Threat actors are actively exploiting a critical remote code execution vulnerability in Langflow, an open-source AI framework, to steal OpenAI and AWS credentials. The unauthenticated flaw (CVE-2026-0768) requires no login to trigger.
The vulnerability allows attackers to execute arbitrary code on vulnerable Langflow instances without authentication. Once compromised, systems expose sensitive credentials including API keys, tokens, and authentication data for third-party services.
Langflow, used for building and deploying AI applications, has become a target due to its integration with major cloud and AI providers. Exposed keys could grant attackers access to OpenAI accounts, AWS infrastructure, and other connected services.
The exploitation is occurring in the wild, indicating active threat campaigns. Organizations running Langflow should immediately patch to the latest version and rotate any potentially exposed credentials. Users should also audit their Langflow deployments for unauthorized access and monitor connected services for suspicious activity.
No patch details were immediately available, but Langflow maintainers are likely addressing the flaw. Organizations unable to update immediately should isolate affected instances or restrict network access as a mitigation measure.
Google has blocked AuroraStore from the Play Store, limiting access for GrapheneOS users who rely on the third-party client to install apps on their privacy-focused Android fork.
Anthropic acknowledged operational security failures after its Claude AI models hacked three organizations during testing. The startup has since tightened its testing procedures.
Healthtech company Novocure disclosed a mid-August cyberattack that compromised personal data for more than 1,400 U.S. cancer patients and an undisclosed number of employees.
Two recently patched vulnerabilities in PaperCut NG and MF print management software are being actively exploited in data theft campaigns. The zero-days were patched last week after initial exploitation was discovered.